Didomi · Vulnerability Disclosure

Didomi Vulnerability Disclosure

Vulnerability disclosure

Didomi runs a coordinated vulnerability disclosure program on Hackerone.

AdvertisingAdTechCCPACMPConsentConsent ManagementDSARData PrivacyGDPRIAB TCFMarTechPreference ManagementPrivacyPrivacy RequestsRegulatory Compliance
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-13'
method: searched
source: https://www.didomi.io/security
info:
  name: Didomi vulnerability disclosure
  provider: didomi
  description: >-
    Didomi publishes a named security contact and an explicit invitation to
    security researchers, in prose, on its security page. It does NOT run a
    public bug bounty and does NOT serve a machine-readable security.txt.
  checked: '2026-08-13'
program:
  exists: true
  type: security-contact
  bug_bounty: false
  platform: null
  contact: security@didomi.io
  policy_url: https://www.didomi.io/security
  policy_text: >-
    "If you are a security researcher who has potentially discovered a security
    weakness or vulnerability in Didomi's systems, please send an email to
    security@didomi.io"
  safe_harbor: not stated
  scope: not published
  response_sla: not published
  rewards: none published
  pgp_key: null
evidence:
- url: https://www.didomi.io/security
  http_status: 200
  finding: >-
    Security contact security@didomi.io published, alongside an ISO/IEC
    27001:2022 certification claim and a description of Didomi's ISMS practices
    (annual policy review, internal and access audits, vendor security
    management, DDoS mitigation, encryption, intrusion detection, penetration
    testing, vulnerability scanning, geographically separated datacenters,
    background checks, mandatory security training).
  fetched: '2026-08-13'
- url: https://didomi.io/.well-known/security.txt
  http_status: 404
  finding: No RFC 9116 security.txt served on the apex.
- url: https://api.didomi.io/.well-known/security.txt
  http_status: 404
  finding: No RFC 9116 security.txt served on the API host.
- url: https://www.didomi.io/security.txt
  http_status: 404
  finding: No security.txt at the legacy root path either.
- url: https://github.com/didomi/security
  http_status: 200
  finding: >-
    A public repo named "security" exists ("Security information for the Didomi
    platform") but its README is two lines and carries no policy — last pushed
    2021-10-21.
- url: https://trust.didomi.io
  http_status: 200
  finding: >-
    A Vanta-hosted trust center is served, but it renders client-side and
    exposed no disclosure policy to an anonymous fetch.
searched_and_absent:
- platform: HackerOne
  result: no Didomi program found
- platform: Bugcrowd
  result: no Didomi program found
- platform: Intigriti
  result: no Didomi program found
remediation:
  - >-
    Publish /.well-known/security.txt on didomi.io AND api.didomi.io per RFC
    9116, with Contact: mailto:security@didomi.io, a Policy: URL, Expires:, and
    Preferred-Languages:. The contact already exists — only the machine-readable
    file is missing, which makes this the cheapest security-posture improvement
    available to Didomi.
  - Publish scope and safe-harbour terms alongside the contact.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/didomi-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.